ZH2003-10SA (security advisory): Mail System Ver. 0.9 Beta
From: G00db0y (G00db0y_at_zone-h.org)
Date: 16 Jul 2003 17:25:44 -0000 To: email@example.com('binary' encoding is not supported, stored as-is)
ZH2003-10SA (security advisory): Mail System Ver. 0.9 Beta.
Name: Mail System Ver. 0.9 Beta
Affected Systems: All versions (?)
Issue: Remote attackers can view all messages (and sql injection
Zone-h Security Team has discovered a serious security flaw in Mail System
Ver. 0.9 Beta.
This is a simple internal mail system, originaly developed for an intranet
Mail System Ver. 0.9 Beta is a simple internal mail system in ASP.
It's possible to retrieve all messages from it.
Everyone can download the database at the following url:
Moreover there is a sql injection vulnerability in the login
It's located at:
From there it's possible to login with these strings:
Login name: ' or 'a'='a
Password: ' or 'a'='a
The vendor has been contacted and a patch is not yet produced
Protect the message file, rewrite the login procedure.
G00db0y - www.zone-h.org admin
Original advisory here: http://www.zone-h.org/en/advisories/read/id=2709/